skills/johnbortotti/skills/foreman/Gen Agent Trust Hub

foreman

Fail

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: HIGHPERSISTENCEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill instructs the agent to establish and manage background maintenance processes using cron jobs ('sweep cron'). This mechanism allows the agent to maintain execution context and perform tasks independently of direct user-initiated sessions.
  • [METADATA_POISONING]: The skill's description states it is 'User-invoked only', yet the instructions mandate autonomous background persistence via crons and include an 'Autonomy' section detailing high-impact actions like merging and cleanup to be performed 'without asking'. This contradiction masks the skill's true level of autonomy and persistent activity.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from a task tracker (Linear) to drive automated workflows, including prompting other agents and making merge decisions. 1. Ingestion points: Project data is retrieved from the Linear tracker using the list_issues and get_issue tools. 2. Boundary markers: The skill does not define delimiters or instructions to isolate external card content from its operational prompts. 3. Capability inventory: The skill has the ability to merge pull requests (gh pr merge), delete worktrees (git worktree prune), and perform network file uploads via curl. 4. Sanitization: No sanitization of the ingested task content is described before it is used to direct worker agents.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 8, 2026, 02:27 AM
Security Audit — agent-trust-hub — foreman